Muhammad Junaid

Cyber Security Professional | Information Security & Network Expert

About

Highly accomplished Cyber Security Professional with 9 years of extensive hands-on experience in Information Security and Network operations, complemented by a Master's Degree. Proven expertise in Security Operations Center (SOC) implementation, incident response, and leading complex IT system administration and cyber security control projects. Adept at leveraging advanced security technologies and project management skills to enhance organizational security postures and mitigate threats effectively.

Work Experience

Security Consultant

LTI Mindtree

Dec 2022 - Present

Jubail, Eastern Province, SA

Currently serving as a Security Consultant at Saudi Aramco Total Refining (SATORP), proactively monitoring and analyzing security alerts to detect and mitigate potential threats.

  • Proactively monitored and analyzed security alerts and logs, identifying potential threats and breaches to enhance organizational security posture.
  • Investigated and assessed security incidents to determine scope, impact, and root cause, ensuring effective incident resolution.
  • Developed and implemented comprehensive incident response plans and procedures, effectively mitigating security incidents and improving response capabilities.
  • Contributed to the development of playbooks using XSOAR for various cyber-security solutions, enhancing automated detection and response capabilities.
  • Stayed abreast of the latest cybersecurity threats, vulnerabilities, and best practices, continuously enhancing incident response capabilities and strategies.

SOAR Consultant

Saudi Business Machine (SBM)

Jul 2021 - Dec 2022

Riyadh, Riyadh Province, SA

Served as a SOAR Consultant at SABIC CORP., developing custom Python scripts to automate security operations and improve incident detection and response.

  • Developed custom Python scripts for integrating 3rd party security products, enhancing automation capabilities for security operations.
  • Automated manual security analyst processes for L1, L2, and L3 tiers, significantly improving operational efficiency and response times.
  • Built and implemented security playbooks, automating detection and response workflows to streamline incident management.
  • Deployed as a SOAR consultant at SABIC CORP., contributing to advanced security orchestration initiatives and enhancing overall security posture.

Cyber Security Consultant

Rewterz Pvt Ltd

Nov 2018 - Jul 2021

Karachi, Sindh, PK

Assisted in the design, delivery, and configuration of diverse security solutions and services for various clients.

  • Assisted in the design and delivery of comprehensive security solutions and services for a diverse client portfolio.
  • Recognized for deploying and configuring various types of security technologies, ensuring robust implementation and operational readiness.

Senior SOAR Engineer

Rewterz Pvt Ltd

Apr 2019 - Dec 2019

Karachi, Sindh, PK

Led the implementation and deployment of Next-Generation SOC environments, leveraging automation and orchestration technologies.

  • Implemented and deployed Next Generation SOC environments, utilizing automation and orchestration technologies across various products.
  • Performed architectural design and build-out of Security Orchestration Automation and Response (SOAR) solutions as a Senior Automation Engineer.
  • Integrated diverse security controls (NGFW, WAF, SIEM, Vulnerability Scanners, threat intelligence tools) through Python-based scripting, enhancing overall security posture.

SOC Analyst

Rewterz Pvt Ltd

Nov 2018 - Apr 2019

Karachi, Sindh, PK

Served as an On-site L2 Security Analyst, responsible for daily SOC operations and vulnerability assessments.

  • Conducted various cyber security tasks, including Vulnerability Assessment and Penetration Testing, identifying critical security weaknesses.
  • Managed daily SOC operations, encompassing Incident Management and Event Management, ensuring timely response to security alerts.
  • Developed and deployed Use Cases aligned with industry and company security standards, enhancing detection capabilities.

Network Security Engineer (NOC/SOC)

Gerry's Group

Dec 2016 - Oct 2018

Karachi, Sindh, PK

Provided technical leadership for projects and shifts, managing and troubleshooting Layer 2 and Layer 3 network infrastructure.

  • Served as Technical Lead, managing technical projects and shifts to ensure smooth network operations.
  • Configured, managed, maintained, and troubleshot Layer 2 and Layer 3 network devices, including Cisco Routers, Switches, Firewalls, and IPS.
  • Maintained various VPN tunnels (GRE) with clients, ensuring secure and reliable connectivity.
  • Managed BGP routing with upstream providers, optimizing network performance and stability.
  • Contributed to the implementation of Use Cases, enhancing network monitoring and security.

Network Support Engineer

Connect communications

Dec 2014 - Nov 2016

Karachi, Sindh, PK

Managed and maintained Cisco switches and ensured efficient network operations, including link aggregation and Spanning Tree Protocol.

  • Managed Cisco Switches on Layer 2 and Layer 3, ensuring optimal network performance and reliability.
  • Analyzed and managed link aggregation/bundling, enhancing network bandwidth and redundancy.
  • Maintained an efficient and secured Spanning Tree Protocol metro ring, preventing network loops and ensuring uptime.

Education

Project Management

PAF-KIET

Jan 2017 - Dec 2019

Karachi, Sindh, PK

Telecommunication

Iqra University

Jan 2011 - Dec 2015

Karachi, Sindh, PK

Languages

English

Skills

Security Technologies & Platforms

  • Application Control (Carbon Black)
  • EDR (Carbon Black)
  • NDR (Dark-Trace)
  • SIEM (QRadar, Splunk, ArcSight)
  • SOAR (SIRP, Phantom, XSOAR)
  • ReSecurity for Threat Intelligence
  • Symantec DLP
  • McAfee ATD Sandboxing
  • Imperva (Secure Sphere, Incapsula)
  • Fireeye (NX, HX, EX, CMX)

Cybersecurity Operations & Analysis

  • SOC (Security Operations Center)
  • Incident Response
  • Cyber Threat Intelligence
  • Proactive Defense
  • Cyber Threat Hunting
  • CyberSOC
  • APT Hunting
  • Cyber Kill Chain
  • Vulnerability Assessment
  • Penetration Testing
  • Incident Management
  • Event Management
  • Use Case Development

Network Security & Infrastructure

  • Cisco Routers
  • Cisco Switches
  • Firewalls
  • IPS (Intrusion Prevention Systems)
  • VPN (GRE)
  • BGP (Border Gateway Protocol)
  • Layer 2/3 Networking
  • Link Aggregation
  • Spanning Tree Protocol

Security Concepts & Methodologies

  • Malware Behaviors
  • Ransomware Behaviors
  • Risk Management Life Cycle
  • Incident Response Management
  • PCI DSS

Programming & Automation

  • Python Scripting
  • Automation
  • Orchestration

Project Management & Leadership

  • Project Scheduling
  • Project Planning
  • Project Execution
  • Technical Leadership